CVE-2025-67601
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Description
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-295
Source
GitHub
Vendor
go
Product
github.com/rancher/rancher
Discussion (0)
Add Comment
No comments yet. Be the first!